Privacy Policy
This policy explains how DocketSync Online handles account information, information you enter, and court-calendar data, on the Law firm, Bail Bond & Small Office, and Personal plans. The September 28 update adds the names and dates of birth entered on the Personal and Bail Bond & Small Office plans, and the card check behind their free trials.
This policy also describes optional calendar sharing. These disclosures describe the service's existing data flows; they do not turn on an integration for you.
What we collect and why
- Account information: firm name, names and email addresses, membership and attorney assignments, sign-in records, and accepted terms version. We use these to provide access and administer your account.
- Firm information: submitted case numbers, client labels, notes, agreed dates, follow-up notes, and activity history. We use these to provide your firm's calendar, reports, and enabled integrations.
- People you track (Personal and Bail Bond & Small Office plans): the first name, last name and date of birth you enter, an optional reference such as a bond number, and on the Personal plan who the person is to you (yourself, your child under 18, or someone who gave permission). We use these only to find that person's cases on the court calendar each business morning and to show them to your account. They are not sent to Stripe, to email or analytics services, or to calendar integrations, and are not used for advertising. Case names shown with a tracked case come from the court calendar, not from what you entered.
- Court-calendar information: licensed data including names, case numbers, hearing details, charges, and dates of birth where available. This information comes from the licensed data source rather than your firm. See Court Data & Disclosures.
- Billing: Stripe customer and subscription identifiers and billing status. Card numbers are entered on Stripe's pages and do not reach our servers. On the Personal and Bail Bond & Small Office plans we also keep a one-way hash of the card fingerprint Stripe provides, so each card gets one free trial; it is not the card number and cannot be turned back into it.
- Usage and security: activity, reports generated, case-page usage, technical logs, and network/browser information used by hosting and security services. These support operation, abuse prevention, troubleshooting, and data-license obligations.
- Connections: provider identity, calendar identifiers, synchronization status, and authorization tokens or app-specific credentials when you connect an external service. Connection credentials are encrypted before storage in our database.
We use contact details for sign-in, account and service messages, support, and digests you enable. We do not sell personal information, use your case list for advertising, or send it to AI services for model training.
Calendar feeds, connections, and webhooks
These features send information to destinations you select. Depending on the feature and available fields:
- Calendar feeds and connections: hearing dates, names, case numbers, session and courtroom, county, charges, attorney assignments, client labels, agreed-date details, and up to the first 200 characters of firm notes can be included in an event. Date of birth is not included in these calendar events.
- Webhooks: firm identity, hearing and change information, charges, attorney assignments, client labels, and agreed-date information are sent to the configured endpoint. Firm notes and dates of birth are not included in the current webhook payload.
- Prints and reports: selected information leaves the app when you download, print, or share it. Print controls let you include notes and dates of birth; those print options are off by default.
Anyone with a private feed link may be able to retrieve its calendar information. Keep the link confidential. People with access to a destination calendar, mailbox, webhook service, or report may be able to see the information you send there. Their access and retention also depend on that service's settings and policies.
Google and Microsoft connections access account identity and calendar metadata to find or create the destination, and create, update, or remove DocketSync events. We do not import the contents of your other calendar events into DocketSync. Practice-management connections may look up matter or case identifiers to link an event. Authorization scopes may permit broader access than these operations; the provider's consent screen shows the requested permissions.
DocketSync Online's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use this information to provide the connection you request, not for advertising or training general-purpose AI models. Access by people is limited to permitted purposes such as support with your consent, security, or legal obligations.
Providers and other recipients
| Provider | Role |
|---|---|
| Supabase | Database and account sign-in. |
| Netlify | Website hosting and server functions, including reports and integrations. |
| Cloudflare | Domain services and Turnstile abuse prevention. Turnstile processes browser and network signals; see its Privacy Addendum. |
| Stripe | Payments, subscriptions, and related fraud/security processing. |
| Resend | Transactional email, including sign-in links and enabled digests. |
| Google Fonts, jsDelivr, cdnjs | Some pages load fonts or application libraries from these services, which receive the browser requests needed to deliver those resources. |
| Your selected calendar or integration provider | Receives information when you enable a feed, connection, or webhook, under that provider's applicable terms and your account settings. |
We also operate a server for extract processing, digests, and calendar synchronization. Authorized operations access is limited to what is needed to run and support the service. Providers may have their own legal, payment, and security responsibilities. We may disclose relevant information when required by law or our data license, or to investigate misuse and protect the service.
Children
The Service is not for use by children, and accounts are for adults only. On the Personal plan a parent or legal guardian may track the court dates of their child under 18; that information is entered by the parent. We do not knowingly collect information directly from children.
Browser storage
The app uses browser storage for sign-in sessions and interface preferences. Hosting and anti-abuse services may process cookies or other technical signals for their functions. Clearing browser storage can sign you out or reset preferences.
Retention and deletion
We keep account and firm information while needed to provide the service, maintain history, and meet billing, security, legal, and data-license obligations. We do not currently promise a fixed automatic deletion date after cancellation.
Removing a case from your active list is a soft removal and does not erase historical records. Removing a tracked person works the same way: their cases stop being tracked, and the entry is kept marked as removed for history, abuse prevention, and data-license obligations. A request to delete your account covers the people you tracked. Cancelling a subscription does not itself request deletion. Email support@opspilot.to to request access, correction, or account deletion. We verify authority, assess what can be deleted, and explain any records that must be retained. Backup copies may remain until their applicable retention cycle ends.
Downloaded, printed, emailed, or synchronized copies may remain outside DocketSync. Removing a connection schedules cleanup of DocketSync-created events and stored connection credentials; cleanup depends on processing and continued provider access and cannot recall copies others have made.
Security and incident notices
We encrypt data in transit, restrict database access by firm and role, and encrypt stored connector credentials. Attorney access is scoped to assigned cases. We use access controls and operational safeguards, but no system can promise absolute security. We provide incident notices as required by applicable law and our contractual obligations, including to account owners and other required recipients.
Your controls
- Manage members and assignments using the controls available to your role.
- Control your digest preference in Account.
- Rotate or disable your private calendar feed link in Account. Subscribers may retain cached copies.
- Pause or remove a calendar connection in Account, and revoke authorization or app-specific credentials with the provider if desired. Revoking access before cleanup may prevent removal of previously written events.
- Manage webhook destinations if your role permits it. Your provider controls its own received copies.
- Use Account to manage or cancel billing, and contact support for privacy requests.
Policy updates
We publish updates here and notify account owners of material changes by email or in the app. New uses requiring consent will be explained before asking for it. Previous Privacy Policy (September 17, 2026) · September 5, 2026.